Find notable cyber news and cases, enriched with sources, timelines, and signals.

LibreOffice malicious spreadsheet code execution security flaw (CVE-2026-63277)

Vulnerability
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

LibreOffice fixed CVE-2026-63277, a flaw that lets a malicious spreadsheet trigger code execution when opened with Java support enabled. The affected scope covers versions before 26.2.5 or 26.8.0, and the vendor has already released updates. A published proof of concept shows the weakness can execute attacker-controlled Java code without the normal macro warning.

Timeline

  1. 06.10.2026 14:57 2 articles · 2h ago

    LibreOffice releases fixes for CVE-2026-63277

    Mitigation Patch Update

    LibreOffice released updates on October 5, 2026 that fixed CVE-2026-63277, a malicious spreadsheet code execution flaw affecting versions before 26.2.5 and 26.8.0; users are advised to upgrade to a fixed version and disable Java if they do not need it.

    Show sources
  2. 06.10.2026 14:57 1 articles · 2h ago

    Researchers disclose a spreadsheet-driven code execution path in LibreOffice

    Initial Disclosure

    Rick de Jager of the V12 security team and Thomas Rinsma and Edoardo Geraci of Codean Labs independently reported CVE-2026-63277, and the V12 team published a proof of concept showing that a Calc spreadsheet can load a database range, download an ODB from a web address, and start a JDBC driver as attacker-controlled Java code when Java support is enabled, bypassing the normal macro trust warning; the proof of concept was tested on Windows and Linux and no real-world abuse has been reported.

    Show sources